Effective
Security
This page explains OXEFY's public security approach and how to report concerns.
Security approach
OXEFY uses reasonable technical and organizational measures appropriate to the nature and current scale of its services. OXEFY does not claim security certifications through this page, and this page is not a detailed security architecture document.
Credential handling
Users are responsible for protecting their accounts, workspace permissions, connected platform access, passwords, API keys, access tokens, private keys, and authorized publishing destinations.
Data transmission and hosting
OXEFY uses HTTPS for its public website and relies on hosting and service providers to deliver website and product functionality. Specific provider controls may vary by service.
Service-provider and platform dependencies
OXEFY products and workflows may depend on hosting providers, form providers, AI providers where applicable, app stores, and third-party platforms. Provider availability, terms, and security practices can affect service behavior.
Secure development and maintenance
OXEFY aims to maintain clear source controls, avoid committing secrets, apply Least-necessary access where practical, review public claims, validate builds, and update services as operational needs evolve.
Monitoring, logging, and abuse prevention
OXEFY may use logs and operational records for reliability, troubleshooting, security, fraud prevention, abuse detection, and enforcement where appropriate.
Backups and continuity
Backup, recovery, and continuity practices may differ by product and provider. OXEFY may retain backups or operational records where needed for reliability, security, or legal reasons.
Responsible reporting
Security reports may be submitted through the Contact form category Security report or by emailing info@oxefy.in. Please include the affected product or page, concise description, safe reproduction steps, potential impact, and contact information.
What not to send
Do not access other users' data, disrupt services, run destructive tests, publish sensitive details before OXEFY has a reasonable opportunity to investigate, or send passwords, secrets, tokens, private keys, exploit payloads, or payment-card data.
Vocalis product security
Product-specific security information for Vocalis is maintained on the Vocalis production website.
Response and remediation
OXEFY reviews reports based on severity, reproducibility, affected service, available information, and applicable law. OXEFY does not operate a public bug bounty and does not promise payment or a fixed remediation time.
Contact
For security concerns, use Contact with Security report or email info@oxefy.in.
Version history
| Version | Date | Status | Change type |
|---|---|---|---|
| 1.1 | 13 September 2026 | Effective | Legal identity, address, and Vocalis policy cross-link harmonization |
| 1.0 | 24 July 2026 | Superseded | Initial effective publication |
Legal notices address
Floor No. 6, Ruia Chambers, In front of Amanora Gold Towers, Amanora Park Town, Hadapsar, Pune – 411028, Maharashtra, India.